IPV6 network communication method, device and system

By modifying the IP address of the terminal and generating connection tracking information, the problem that the network security settings in IPV6 network communication cannot identify downlink data packets for service connections is solved, ensuring that the terminal can access the data network and realize service connections.

CN113923186BActive Publication Date: 2025-05-23HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010575876.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-22
Publication Date
2025-05-23
Estimated Expiration
2040-06-22

AI Technical Summary

Technical Problem

In IPV6 network communication, the IP address of the terminal does not include the IPV6 prefix configured by the data network to the network device, resulting in the network security settings that cannot identify the downlink data packets belonging to the service connection initiated by the terminal, thereby blocking the service connection.

Method used

By modifying the source IP address of the uplink packet sent by the terminal to the data network, it includes the IPV6 prefix configured by the data network to the network device, and generating connection tracking information, indicating that the destination IP address of the downlink packet is the modified IP address.

Benefits of technology

Ensure that network security settings can identify and allow downlink data packets belonging to service connections initiated by the terminal, avoid blocking the terminal's service connection to the data network, and ensure that the terminal can access the data network to realize specific services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113923186B_ABST
    Figure CN113923186B_ABST
Patent Text Reader

Abstract

The present application provides an IPV6 network communication method, device and system. The method includes: a network device receives an uplink data packet sent by a terminal to a data network, and the uplink data packet is used to request to establish a service connection. Then, the source IP address of the uplink data packet is modified to a first IP address, and the modified uplink data packet is sent to the data network, wherein the first IP address includes the IPV6 prefix configured by the data network to the network device; in addition, the network device can also generate connection tracking information for the service connection, wherein the connection tracking information indicates that the destination IP address of the downlink data packet from the data network and belonging to the service connection is the first IP address. According to the technical solution of the present application, the network security setting can identify the downlink data packet belonging to the service connection initiated by the terminal, and will not block the service connection initiated by the terminal to the data network, ensuring that the terminal can access the data network to implement specific services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communications, and in particular to IPv6 network communication methods, devices and systems. Background Art

[0002] A network device running in an Internet Protocol version 6 (IPV6) full routing mode can receive IPV6 prefixes configured by multiple data networks for the network device. A terminal can generate its own Internet Protocol (IP) address, wherein the IP address can include one of the IPV6 prefixes received by the network device.

[0003] When the IP address of a terminal does not include an IPV6 prefix configured by a data network to a network device, in order to ensure that the terminal can access the data network to implement specific services, it is usually necessary to use the network device to modify the source IP address and / or destination IP address of the data packets that the terminal interacts with the data network. At the same time, in order to prevent the downlink data packets belonging to the service connection initiated by the terminal from being terminated / discarded by the network security settings enabled by the network device, the network security settings need to be turned off, but this will bring network security risks. Summary of the invention

[0004] An IPV6 network communication method, apparatus and system are provided in the embodiments of the present application. Even if the IP address of the terminal does not include the IPV6 prefix configured by the data network to the network device, the network security settings enabled by the network device can identify the downlink data packets belonging to the service connection initiated by the terminal, and will not block the service connection initiated by the terminal to the data network, thereby ensuring that the terminal can access the data network to implement specific services.

[0005] In a first aspect, an IPV6 network communication method is provided, which can be performed by a communication device. The communication device can be a network device, or a chip or system on chip deployed in the network device. The method includes: the communication device first receives an uplink data packet sent by a terminal to a first data network, wherein the uplink data packet is used to request to establish a service connection. Then, the source IP address of the uplink data packet is modified to a first IP address, and the modified uplink data packet is sent to the first data network, wherein the first IP address includes an IPV6 prefix configured by the first data network to the network device; in addition, the communication device can also generate connection tracking information for the service connection, wherein the connection tracking information indicates that the destination IP address of the downlink data packet from the first data network and belonging to the service connection is the first IP address.

[0006] In this way, for downlink data packets coming from the data network and belonging to the service connection, even if the network device enables the network security settings, the network security settings can identify the downlink data packets as downlink data packets belonging to the service connection based on the indication of the connection tracking information included in the service connection. That is, the downlink data packets belonging to the service connection will be determined by the network security settings as data packets belonging to the service connection initiated by the terminal, and the downlink data packets will not be terminated / discarded by the network security settings, thereby ensuring that the terminal can access the data network through the network device to realize the corresponding service.

[0007] In other words, even if the terminal's IP address does not include the IPV6 prefix configured by the data network to the network device, the security settings enabled by the network device can identify the downlink data packets belonging to the service connection initiated by the terminal and will not block the service connection initiated by the terminal to the data network, thereby ensuring that the terminal can access the data network to implement specific services.

[0008] In a second aspect, a communication device is provided, which includes a unit or means for executing each step in the above first aspect.

[0009] In a third aspect, a communication device is provided, the communication device comprising a processor and an interface circuit. The processor is used to communicate with other devices through the interface circuit and execute the method provided in the first aspect above.

[0010] In a fourth aspect, a communication device is provided, the communication device comprising a processor connected to a memory, and configured to call a program stored in the memory to execute the method provided in the first aspect. The memory may be located inside the communication device or outside the communication device.

[0011] In a fifth aspect, a network device is provided, comprising the communication apparatus provided in any of the above aspects.

[0012] In a sixth aspect, a network system is provided, comprising a terminal, a first data network, and a communication device / network equipment provided in any of the above aspects. In some possible designs, the network system may also include a second data network, and the IP address of the terminal includes an IPV6 prefix configured by the second data network to the network equipment.

[0013] In a seventh aspect, a computer-readable storage medium is provided for storing instructions, which, when executed by a processor of a communication device, enables the communication device to implement the method provided in the first aspect.

[0014] In an eighth aspect, a computer program is provided, which, when executed by a processor, is used to execute the method provided in the first aspect above.

[0015] In a ninth aspect, a computer program product is provided, which may include the computer-readable storage medium provided in the seventh aspect, wherein the computer-readable storage medium includes the computer program provided in the eighth aspect.

[0016] In a tenth aspect, a chip is provided, the chip including a processor for implementing the functions of the communication device provided in the above-mentioned various aspects, for example, receiving or processing the data and / or information involved in the method of the above-mentioned first aspect. In a possible design, the chip also includes a memory for storing program instructions and / or data.

[0017] In the above aspects, the processor may be implemented by hardware or by software. When the processor is implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc. When the processor is implemented by software, the processor may be a general-purpose processor implemented by reading software code stored in a memory; wherein the memory may be integrated in the processor or may be located outside the processor and exist independently.

[0018] In the above aspects, the number of processors included in the communication device may be one or more, and the number of memories may be one or more. The memory may be integrated with the processor, or the memory and the processor may be separately arranged. In the specific implementation process, the memory may be integrated with the processor on the same chip, or may be arranged on different chips respectively. The type of memory and the arrangement method of the memory and the processor are not limited in the embodiments of the present application.

[0019] In the above aspects, the information transmission or reception process may be a process in which the processor sends and receives information. For example, the process of sending an uplink data packet may be an uplink data packet outputted from the processor; the process of receiving an uplink data packet may be an uplink data packet received by the processor. Specifically, the uplink data packet outputted by the processor may be outputted to a transmitter, and the uplink data packet received by the processor may be from a receiver. The transmitter and the receiver may be collectively referred to as a transceiver.

[0020] In the above aspects, the source IP address of the uplink data packet from the terminal can be a second IP address, and the second IP address includes a second IPV6 prefix configured by the second data network to the network device. Accordingly, the communication device can perform an IPV6-to-IPv6 Network Prefix Translation (NPTV6) on the second IP address according to the first IPV6 prefix to obtain the first IP address. In this way, after the source IP address of the uplink data packet from the terminal is modified to the first IP address, the application layer checksum of the modified uplink data packet is the same as that of the uplink data packet before the modification, and there is no need to recalculate the application layer checksum of the modified uplink data packet.

[0021] In the above aspects, the communication device can also receive a downlink data packet from the first data network and belonging to the service connection, and modify the destination IP address of the downlink data packet to the source IP address of the uplink data packet from the terminal, and then send the modified downlink data packet to the terminal. In this way, the terminal and the data network can complete the establishment of a service connection and implement a specific service based on the service connection.

[0022] In the above aspects, when the communication device receives a downlink data packet from the first data network and belonging to the service connection, the connection state of the connection tracking information may be set to indication information indicating a successful connection.

[0023] In the above aspects, the first data network may include but is not limited to an internet protocol television (IPTV) network or a cloud virtual reality (Cloud VR) network.

[0024] In the above aspects, the second data network may include but is not limited to the Internet. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 A schematic diagram of a business scenario to which the technical solution of an embodiment of the present application is applicable.

[0026] Figure 2 A schematic diagram of the structure of an IP address including an IPV6 prefix.

[0027] Figure 3 This is a flow chart of a communication method provided in an embodiment of the present application.

[0028] Figure 4 This is a schematic diagram of the process of communication between a terminal and a data network in an embodiment of the present application.

[0029] Figure 5 A schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0030] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0031] Figure 1 Schematic diagram of a business scenario to which the technical solution of the embodiment of the present application is applicable. Figure 1As shown, the network device 10 can allocate a service set identifier (SSID), configure multiple Ethernet interfaces such as ETH0, ETH1, and ETH2, and configure multiple wide area network interfaces such as WAN0, WAN1, and WAN2. It can be understood that Figure 1 The structure of the network device 10 does not constitute a limitation on the specific structure of the network device. The network device 10 may be configured with more or fewer Ethernet interfaces and more or fewer WAN interfaces. The identifiers of each Ethernet interface and each WAN interface may be replaced with real values.

[0032] The network device 10 can be connected to one or more data networks for supporting specific services. For example, the network device 10 can be connected to data networks for supporting specific services such as the Internet, IPTV network, and Cloud VR network through multiple different WAN interfaces. Different data networks can configure different IPV6 prefixes for the network device 10, which can be configured by upper-layer servers, network management devices, or other devices in the data network.

[0033] Among them, the data network can maintain a route from the data network to the network device 10 according to the IPV6 prefix configured by the data network to the network device. Accordingly, for a downlink data packet to be sent to a terminal connected to the network device 10, the data network can send the downlink data packet to the network device 10 according to the route corresponding to the IPV6 prefix if and only if the destination IP address of the downlink data packet includes the IPV6 prefix.

[0034] A terminal equipped with a wireless communication module can be connected to the network device 10 according to the SSID assigned by the network device 10. For example, a mobile phone and a virtual reality (VR) device can be connected to the network device 10 according to the SSID assigned by the network device 10. A terminal equipped with an interface device for connecting a communication cable can be connected to the Ethernet interface of the network device 10 through a corresponding communication cable. For example, a personal computer (PC) and a set-top box (STB) can be connected to the Ethernet interface of the network device 10 through a corresponding communication cable. It can be understood that the aforementioned various terminals may be directly connected to the network device 10 or may be connected to an access point (AP); wherein the AP may be connected to the network device 10 according to the SSID assigned by the network device 10, or may be connected to the Ethernet interface of the network device 10 through a corresponding communication cable. The terminal connected to the network device 10 may also be of other types, such as an augmented reality (AR) device.

[0035] The terminal can generate its own IP address according to one of the IPV6 prefixes configured by the network device 10. Figure 2 As shown, the IP address generated by the terminal may include a network portion and an interface portion. The interface portion may include a 64-bit interface identifier generated by the terminal according to its own MAC address. The network portion may include one of the IPV6 prefixes configured by the network device 10, and may optionally include a 16-bit subnet identifier; for example, the network portion may include a 16-bit subnet identifier and a 48-bit IPV6 prefix.

[0036] It can be understood that the network device 10 can track the service connection and generate connection tracking information (or connection record item) of the service connection. The connection tracking information may include uplink connection information and downlink connection information, and may also include other information such as protocol type and protocol number. The uplink connection information may at least include the source IP address and destination IP address of the uplink data packet from the terminal and belonging to the service connection; the downlink connection information may at least include the source IP address and destination IP address of the downlink data packet that the network device 10 expects to receive and belongs to the service connection.

[0037] In addition, depending on the protocol type of the service connection, the uplink connection information and the downlink connection information may also include one or more other information. For example, for the connection tracking information of a transmission control protocol (TCP) connection, its uplink connection information may also include: the source port number and the destination port number of the uplink data packet belonging to the TCP connection, and its downlink connection information may also include: the source port number and the destination port number of the downlink data packet that the network device 10 expects to receive and belongs to the service connection.

[0038] The network device 10 may enable network security settings, where the network security settings may include but are not limited to a firewall or an application layer gateway (ALG). For a downlink data packet from a data network, the network security settings may determine whether the downlink data packet belongs to a service connection initiated by a terminal based on the connection tracking information generated by the network device 10. For example, the connection information of the downlink data packet from the data network may be obtained, and the connection information may include but is not limited to the source IP address and the destination IP address of the downlink data packet; then the connection information of the downlink data packet is matched with the downlink connection of each connection tracking information generated by the network device; if there is a downlink connection information of a connection tracking information that is the same as the connection information of the downlink data packet, it means that the downlink data packet belongs to the service connection corresponding to the connection tracking information, and accordingly it can be determined that the downlink data packet belongs to the service connection initiated by the terminal.

[0039] If the downlink data packet is determined to belong to a service connection initiated by the terminal, the downlink data packet will be forwarded to the corresponding terminal by the network device 10; otherwise, the downlink data packet will be terminated / discarded by the network security setting, so that the downlink data packet will not be forwarded to the corresponding terminal by the network device 10. In other words, the network device 10 can enable the network security setting to allow the terminal to initiate a service connection to the data network, block the service connection initiated by the data network to the terminal, and filter the downlink data packets from the data network that may be used to attack the terminal, so as to prevent intruders from using the data network to attack the terminal.

[0040] If the IP address of the terminal does not include the IPV6 prefix configured by the data network to the network device 10, when the network device 10 receives an uplink data packet sent by the terminal to the data network, and the uplink data packet is used to request the establishment of a service connection, the network device 10 needs to modify the source IP address of the uplink data packet to a new IP address, and the new IP address includes the IPV6 prefix configured by the data network to the network device 10. In this way, after the modified uplink data packet is sent to the data network, the data network can send a downlink data packet belonging to the service connection to the network device 10, wherein the destination IP address of the downlink data packet is the new IP address.

[0041] In this case, in the connection tracking information of the service connection to which the uplink data packet belongs, the downlink connection information may indicate that the destination IP address of the downlink data packet of the service connection is the IP address of the terminal, that is, the destination IP address of the downlink data packet that the network device 10 expects to receive and belongs to the service connection is the IP address of the terminal. However, the destination IP address of the downlink data packet belonging to the service connection is a new IP address, and the network security setting cannot identify the downlink data packet belonging to the service connection based on the connection tracking information of the service connection, or the downlink data packet belonging to the service connection will be mistakenly determined as a downlink data packet that does not belong to the service connection initiated by the terminal, resulting in the downlink data packet belonging to the service connection being terminated / discarded by the network security setting enabled by the network device. Accordingly, in order to prevent the downlink data packet belonging to the service connection initiated by the terminal from being terminated / discarded by the network security setting, the network security setting needs to be turned off.

[0042] In view of this, at least one communication method, device and system is provided in the embodiments of the present application. The network device first receives an uplink data packet sent by the terminal to the data network, wherein the uplink data packet is used to request to establish a service connection. Then, the source IP address of the uplink data packet is modified to a first IP address, and the modified uplink data packet is sent to the data network, wherein the first IP address includes an IPV6 prefix configured by the data network to the network device; in addition, the network device can also generate connection tracking information for the service connection, wherein the connection tracking information indicates that the destination IP address of the downlink data packet from the data network and belonging to the service connection is the first IP address. In this way, for a downlink data packet from the data network and belonging to the service connection, the network security setting can identify the downlink data packet as a downlink data packet belonging to the service connection according to the indication of the connection tracking information of the service connection, or the downlink data packet belonging to the service connection will be determined by the network security setting as a data packet belonging to the service connection initiated by the terminal, and the downlink data packet will not be terminated / discarded by the network security setting, ensuring that the terminal can access the data network through the network device to implement the corresponding service.

[0043] In other words, even if the terminal's IP address does not include the IPV6 prefix configured by the data network to the network device, the security settings enabled by the network device can identify the downlink data packets belonging to the service connection initiated by the terminal and will not block the service connection initiated by the terminal to the data network, thereby ensuring that the terminal can access the data network to implement specific services.

[0044] Figure 3 Flow chart of a communication method provided in an embodiment of the present application. Figure 3 As shown, the method may at least include the following steps.

[0045] Step 301: A network device receives an uplink data packet sent by a terminal to a data network.

[0046] The source IP address of the uplink data packet may include or not include the IPv6 prefix configured by the data network to the network device, and the uplink data packet is used to request to establish a service connection. The service connection may include but is not limited to a TCP connection or a user datagram protocol (UDP) connection, and may also include an internet control message protocol (ICMP) connection. The source IP address of the uplink data packet is the IP address of the terminal.

[0047] The data network may include but is not limited to the Internet, IPTV network or Cloud VR network.

[0048] Step 303: The network device modifies the source IP address of the uplink data packet to the first IP address, and sends the modified uplink data packet to the data network.

[0049] The first IP address includes the IPv6 prefix configured by the data network to the network device, so that the data network can send a downlink data packet belonging to the service connection and having the first IP address as the destination IP address to the network device.

[0050] Step 305: Generate connection tracking information for the service connection.

[0051] The connection tracking information indicates that the destination IP address of the downlink data packet from the data network and belonging to the service connection is the first IP address. The network security setting can identify the downlink data packet belonging to the service connection according to the indication of the connection tracking information of the service connection, and will not terminate / discard the downlink data packet belonging to the service connection, thereby ensuring that the terminal can access the data network to implement the corresponding service.

[0052] In summary, even if the IP address of the terminal does not include the IPV6 prefix configured by the data network to the network device, the network security settings enabled by the network device can identify the downlink data packets belonging to the service connection initiated by the terminal and will not block the service connection initiated by the terminal to the data network, thereby ensuring that the terminal can access the data network to implement specific services.

[0053] Combine the following Figure 1 The service scenario shown in FIG. 1 is used to exemplarily describe the process of the terminal communicating with the data network. Taking the case where the IP address of the STB includes the IPV6 prefix configured by the Internet to the network device, and the STB accesses the IPTV network to implement the corresponding IPTV service as an example, the process of the STB communicating with the IPTV network may include the following steps 401 to 411. Among them, other data networks may be used to replace the IPTV network. Figure 4 The Internet and / or IPTV network in the illustrated embodiment can be obtained by replacing STB with other types of terminals. Figure 4 The embodiments shown are based on the same technical solution.

[0054] Step 401: The IPTV network configures a first IPv6 prefix to a network device, and the Internet configures a second IPv6 prefix to the network device.

[0055] Step 402: The network device sends the second IPv6 prefix to the STB.

[0056] It is understandable that a network device may be connected to multiple types of terminals, and multiple types of terminals may need to access the Internet, but only one or more specific types of terminals need to access other data networks, resulting in the number of data packets interacting between the network device and the Internet being far greater than the number of data packets interacting between the network device and other data networks.

[0057] Accordingly, in order to reduce the load on the network device and enable the network device to modify the source IP address / destination IP address of a relatively small number of data packets, in one possible implementation, the network device may only broadcast the second IPV6 prefix from the Internet, so that the IP addresses generated by each terminal including the STB include the second IPV6 prefix.

[0058] Step 403: The STB generates its own IP address according to the second IPv6 prefix.

[0059] The IP address generated by the STB may include a second IPv6 prefix and a 64-bit interface identifier, which is generated by the STB according to its own media access control (MAC) address. For ease of description, the IP address generated by the STB is referred to as the second IP address in subsequent steps.

[0060] Step 404: The STB sends an uplink data packet to the data network for requesting to establish a service connection.

[0061] It can be understood that after the network device receives the uplink data packet from the STB, it can identify whether the uplink data packet is an uplink data packet for requesting to establish a service connection based on the payload (Payload) carried in the uplink data packet. Alternatively, the connection information of the uplink data packet can be obtained from the uplink data packet, such as the source IP address and destination IP address of the uplink data packet; then, based on the connection information, it is determined whether the connection tracking information of the service connection to which the uplink data packet belongs already exists in the network device; if not, it means that the uplink data packet is an uplink data packet for requesting to establish a service connection.

[0062] When the network device receives an uplink data packet from the STB for requesting to establish a service connection, step 405 may be executed to determine a data network for receiving the uplink data packet according to the destination IP address of the uplink data packet.

[0063] If the data network used to receive the uplink data packet is the Internet, the uplink data packet can be transmitted to the Internet via a high-speed Internet (HSI) service traffic channel between the network device and the data network, and the relevant processing process of the network device 10 for the uplink data packet is not repeated here.

[0064] If the data network used to receive the uplink data packet is an IPTV network, the network device may execute step 406 to convert the source IP address of the uplink data packet according to the first IPv6 prefix to obtain a first IP address.

[0065] Here, the source IP address of the uplink data packet (ie, the second IP address) may be converted using NTPV6, ie, the source IP address of the uplink data packet may be converted based on the RFC6292 algorithm.

[0066] For the first IP address obtained by the network device 10, after the source IP address of the uplink data packet is replaced with the first IP address in the subsequent process, the application layer checksum of the uplink data packet will not be changed, and there is no need to recalculate the application layer checksum of the modified uplink data packet.

[0067] In addition, if the length of the first IPV6 prefix is ​​not greater than 48 bits, only the upper 64 bits of the second IP address need to be modified, and there is no need to modify the interface identifier of the second IP address; if the length of the first IPV6 prefix is ​​greater than 48 bits, the upper 64 bits of the second IP address need to be modified, and 16 bits of the interface identifier need to be modified. In this way, the interface part of the first IP address is the same as or highly similar to the interface identifier of the second IP address, and the interface part of the first IP address can more accurately express the MAC address of the STB. For the modified uplink data packet, it is very easy to trace the source of the uplink data packet according to the interface part of the first IP address, which is conducive to quickly determining that the terminal sending the uplink data packet is STB.

[0068] Exemplarily, the second IPV6 prefix configured by the Internet to the network device is 2015:2015:0:6a, the first IPV6 prefix configured by the IPTV network to the network device is 2002:0:0:0, and the interface identifier generated by the STB is 6987:9945:8ec1:1065. The source IP address of the uplink data packet sent by the STB to the IPTV network is 2015:2015:0:6a:6987:9945:8ec1:1065. NPTV6 is performed on the second IP address 2015:2015:0:6a:6987:9945:8ec1:1065 according to the first IPV6 prefix "2002:0:0:0", and the first IP address obtained is 2002:0:0:0:8a19:9945:8ec1:106. After the network device replaces the source IP address of the uplink data packet from 2015:2015:0:6a:6987:9945:8ec1:1065 to 2002:0:0:0:8a19:9945:8ec1:1065 in the subsequent process, the application layer checksum of the uplink data packet is not changed. The interface part "8a19:9945:8ec1:1065" of the first IP address has a high similarity with the interface identifier "6987:9945:8ec1:1065", and it is easy to locate the STB that sends the uplink data packet based on the interface part of the first IP address.

[0069] Step 407: The network device generates connection tracking information for the service connection.

[0070] The downlink connection information of the connection tracking information may indicate that the destination IP address of the downlink data packet belonging to the service connection is the first IP address. The network device may also set the connection state of the connection tracking information to NEW, or set the connection state of the connection tracking information to indication information indicating a newly added connection.

[0071] In the embodiment of the present application, for the connection tracking information of a service connection, the destination IP address of its uplink connection information is the same as the source IP address of its downlink connection information. The source IP address of its uplink connection information is the source IP address of the uplink data packet from the terminal and belonging to the service connection, that is, the source IP address of the uplink connection information is the second IP address generated by the terminal; the destination IP address of its downlink connection information is the modified source IP address of the uplink data packet, that is, the destination IP address of the downlink connection information is the first IP address generated by the network device.

[0072] Taking the example of STB sending an uplink data packet to the IPTV network to request to establish a service connection, the network device can obtain the source IP address IP_1 and the destination IP address IP_2 of the uplink data packet, and the network device performs NPTV6 on IP_1 to obtain the first IP address IP_3. The connection tracking information of the service connection generated by the network device is shown in Table 1 below.

[0073] Table 1

[0074] Source IP address Destination IP address Uplink connection information IP_1 IP_2 Downlink connection information IP_2 IP_3

[0075] As shown in Table 1 above, in the connection tracking information of the service connection, the destination IP address included in the uplink connection information and the source IP address included in the downlink connection information are both IP_2. The source IP address included in the uplink connection information is different from the destination IP address included in the downlink connection information; the source IP address included in the uplink connection information is the source IP address IP_1 of the uplink data packet from the terminal and belonging to the service connection, and the destination IP address included in the downlink connection information is the first IP address IP_3. In other words, the downlink connection information indicates that the destination IP address of the downlink data packet that the network device expects to receive and belongs to the service connection is IP_3.

[0076] In specific implementation, the NPTV6 / RFC6292 algorithm can be embedded in the network device to realize the functional module for connection tracking of the service connection, so that in the connection tracking information generated by the network device, the destination IP address included in the downlink connection information is the first IP address obtained by converting the IP address of the terminal using the NPTV6 / RFC6292 algorithm, so that the network device can enable the network security setting to block the service connection initiated by the data network. Specifically, the network device can be compatible with various application layer security technologies such as firewalls, ALGs, and port mappings.

[0077] In step 408, the network device modifies the source IP address of the uplink data packet to the first IP address, and sends the modified uplink data packet to the IPTV network. In other words, the uplink data packet sent by the terminal to the IPTV network, i.e., the IPTV service traffic, can be transmitted to the IPTV network through the IPTV service traffic channel between the network device 10 and the IPTV network.

[0078] Step 409: The network device receives a downlink data packet belonging to the service connection sent by the IPTV network to the network device.

[0079] The destination IP address of the downlink data packet belonging to the service connection is the first IP address.

[0080] Step 410: The network device determines whether connection tracking information of the service connection to which the downlink data packet belongs already exists.

[0081] In a possible implementation, the network device may obtain connection information from the data network, wherein the connection information may include at least the source IP address and the destination IP address of the downlink data packet. If, among the connection tracking information generated by the network device, there is a piece of connection tracking information whose downlink connection information is the same as the connection information of the downlink data packet, it can be determined that the piece of connection tracking information is the connection tracking information of the service connection to which the downlink data packet belongs, or it can be determined that the connection tracking information of the service connection to which the downlink data packet belongs already exists. Accordingly, the network security setting enabled by the network device can determine that the downlink data packet belongs to a downlink data packet of the service connection initiated by the terminal, the network security setting will not terminate / discard the downlink data packet, and the network device can execute the following steps 411 and 412.

[0082] Step 411: Set the connection status of the connection tracking information of the service connection to which the downlink data packet belongs to the indication information indicating a successful connection, for example, set the indication information of the connection tracking information from NEW to ESTABLISHED.

[0083] Among them, the network device sets the connection status of the connection tracking information of the service connection to which the downlink data packet belongs to to the indication information indicating a successful connection only when it receives the downlink data packet belonging to a service connection initiated by the STB for the first time, so that the network security setting can perceive that the STB has successfully established a service connection with the IPTV network.

[0084] Step 412: modify the destination IP address of the downlink data packet to the second IP address, and send the modified downlink data packet to the STB.

[0085] The network device may modify the destination IP address of the downlink data packet to the source IP address included in the uplink connection information of the connection tracking information of the service connection based on the connection tracking information of the service connection. Alternatively, the network device may register the correspondence between the first IP address and the second IP address in a Network Address Translation (NAT) table, and modify the destination IP address of the downlink data packet from the first IP address to the second IP address based on the correspondence recorded in the NAT table. The downlink data packet belonging to the service connection can be sent to the STB, so that the service connection can be established between the STB and the IPTV network and the IPTV service can be implemented based on the service connection.

[0086] Based on the same concept as the aforementioned method embodiments, a communication device 500 is also provided in an embodiment of the present application. The communication device 500 includes units or means for implementing each step performed by a network device in any of the above methods.

[0087] like Figure 5 As shown, the communication device 500 may include: a receiving unit 501, used to receive an uplink data packet sent by a terminal to a first data network, wherein the uplink data packet is used to request to establish a service connection. A processing unit 502, used to modify the source IP address of the uplink data packet to a first IP address, wherein the first IP address includes a first IPV6 prefix configured by the first data network to a network device; and also used to generate connection tracking information for the service connection, wherein the connection tracking information indicates that the destination IP address of the downlink data packet from the first data network and belonging to the service connection is the first IP address. A sending unit 503, used to send the modified uplink data packet to the first data network.

[0088] It should be understood that the division of the units in the above communication device is only a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. And the units in the communication device can all be implemented in the form of software calling through processing elements; they can also be all implemented in the form of hardware; some units can also be implemented in the form of software calling through processing elements, and some units can be implemented in the form of hardware. For example, each unit can be a separately established processing element, or it can be integrated in a certain chip of the device. In addition, it can also be stored in the memory in the form of a program, and called and executed by a certain processing element of the communication device. The function of the unit. In addition, all or part of these units can be integrated together, or they can be implemented independently. The processing element described here can also be a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each unit above can be implemented by an integrated logic circuit of hardware in the processor element or in the form of software calling through a processing element.

[0089] In one example, the unit in any of the above communication devices may be one or more integrated circuits configured to implement the above method, such as: one or more application specific integrated circuits (ASIC), or one or more microprocessors (digital signal processors, DSP), or one or more field programmable gate arrays (FPGA), or a combination of at least two of these integrated circuit forms. For another example, when the unit in the communication device can be implemented in the form of a processing element scheduler, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call a program. For another example, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0090] The above unit for receiving is an interface circuit of the communication device, which is used to receive signals from other devices. For example, when the communication device is implemented in the form of a chip, the receiving unit is an interface circuit of the chip used to receive signals from other chips or devices. The above unit for sending is an interface circuit of the communication device, which is used to send signals to other devices. For example, when the communication device is implemented in the form of a chip, the sending unit is an interface circuit of the chip used to send signals to other chips or devices.

[0091] In one implementation, the unit for implementing each step in the above method by the network device can be implemented in the form of a processing element scheduling program. For example, the device for the network device includes a processing element and a storage element. The processing element calls the program stored in the storage element to execute the method executed by the network device in the above method embodiment. The storage element can be a storage element on the same chip as the processing element, that is, an on-chip storage element, or a storage element on a different chip from the processing element, that is, an off-chip storage element.

[0092] The units of the network device implementing the various steps in the above method can be integrated together and implemented in the form of a system on chip. For example, the baseband device includes a SOC chip, which is used to implement the method executed by the above network device. The chip can integrate at least one processing element and a storage element, and the method executed by the above network device can be implemented in the form of a program stored in the storage element by the processing element; or, the chip can integrate at least one integrated circuit to implement the method executed by the above network device; or, the above implementation methods can be combined, and the functions of some units can be implemented in the form of a processing element calling a program, and the functions of some units can be implemented in the form of an integrated circuit.

[0093] It can be seen that the above communication device for network equipment may include at least one processing element and an interface circuit, wherein at least one processing element is used to execute any one of the methods provided in the above method embodiments and performed by the network equipment. The processing element may execute part or all of the steps executed by the network equipment in a first manner: that is, by calling a program stored in a storage element; or in a second manner: that is, by combining an integrated logic circuit of hardware in a processor element with instructions to execute part or all of the steps executed by the network equipment; of course, part or all of the steps executed by the above network equipment may also be executed in combination with the first manner and the second manner.

[0094] The processing element here is the same as described above, and can be a general-purpose processor, such as a CPU, or can be configured as one or more integrated circuits, such as: one or more ASICs, or, one or more microprocessors DSPs, or, one or more FPGAs, etc., or a combination of at least two of these integrated circuit forms.

[0095] A storage element may be a memory or a collective term for multiple storage elements.

[0096] An IPV6 network communication system is also provided in the embodiment of the present application, including a terminal, a data network, and a communication device / network device provided in any embodiment of the present application. It is understood that the communication system may include one or more terminals of the same or different types, and one or more data networks each used to support different services.

[0097] It should be noted that, unless otherwise specified, the " / " in this application means or, for example, A / B can mean A or B. The "and / or" in this application is only a description of the association relationship of associated objects, indicating that there can be three relationships; for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, for elements (element) in the singular form "a", "an" and "the", unless the context clearly stipulates otherwise, it does not mean "one or only one", but means "one or more than one". For example, "a device" means one or more such devices. Furthermore, "at least one (at least one of)..." means one or any combination of the subsequent associated objects, for example, "at least one of A, B and C" includes A, B, C, AB, AC, BC, or ABC. Determining Y based on X does not mean determining Y based only on X, but Y can also be determined based on X and other information.

[0098] It should be noted that the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. The terms "include", "comprises", "has" and their variations all mean "including but not limited to", unless otherwise specifically emphasized.

[0099] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of the present application.

[0100] It should be understood that in various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, but not to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions provided in the aforementioned embodiments can still be modified, or some of the technical features therein can be replaced by equivalents, and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions provided in the various embodiments of the present application.

Claims

1. An IPV6 network communication method, It is characterized in that Applied to network equipment, including: Receiving an uplink data packet sent by a terminal to a first data network; wherein the uplink data packet is used to request to establish a service connection; wherein the IP address of the terminal does not include an IPV6 prefix configured by the first data network to a device located in the network; Modify the source Internet Protocol IP address of the uplink data packet to a first IP address, and send the modified uplink data packet to the first data network; wherein the first IP address includes a first Internet Protocol Version 6 IPV6 prefix configured by the first data network to the network device; and, Generate connection tracking information for the service connection; wherein the connection tracking information indicates that the destination IP address of a downlink data packet from the first data network and belonging to the service connection is the first IP address.

2. The method according to claim 1, It is characterized in that The source IP address of the uplink data packet is a second IP address, and the second IP address includes a second IPv6 prefix configured by the second data network to the network device; Before modifying the source IP address of the uplink data packet to the first IP address, the method further includes: According to the first IPV6 prefix, an IPV6 to IPV6 network prefix conversion NPTV6 is performed on the second IP address to obtain a first IP address.

3. The method according to claim 2, It is characterized in that The first data network includes an Internet Protocol Television IPTV network or a cloud virtual reality VR network; The second data network includes the Internet.

4. The method according to any one of claims 1 to 3, It is characterized in that The method further comprises: receiving a downlink data packet from the first data network and belonging to the service connection; Modify the destination IP address of the downlink data packet to the source IP address of the uplink data packet; and set the connection status of the connection tracking information to indication information indicating successful connection; Send the modified downlink data packet to the terminal.

5. A communication device, It is characterized in that include: A receiving unit, configured to receive an uplink data packet sent by a terminal to a first data network; wherein the uplink data packet is used to request to establish a service connection; wherein the IP address of the terminal does not include an IPV6 prefix configured by the first data network to a device located in the network; A processing unit, configured to modify the source Internet Protocol IP address of the uplink data packet to a first IP address; wherein the first IP address includes a first Internet Protocol Version 6 IPV6 prefix configured by the first data network to the network device; The processing unit is further configured to generate connection tracking information of the service connection; wherein the connection tracking information indicates that the destination IP address of the downlink data packet from the first data network and belonging to the service connection is the first IP address; A sending unit is used to send the modified uplink data packet to the first data network.

6. The communication device according to claim 5, It is characterized in that The source IP address of the uplink data packet is a second IP address, and the second IP address includes a second IPv6 prefix configured by the second data network to the network device; The processing unit is further used to perform IPV6 to IPV6 network prefix conversion NPTV6 on the second IP address according to the first IPV6 prefix to obtain the first IP address.

7. The communication device according to claim 6, It is characterized in that The first data network includes an Internet Protocol Television IPTV network or a cloud virtual reality VR network; The second data network includes the Internet.

8. The communication device according to any one of claims 5 to 7, It is characterized in that The receiving unit is further configured to receive a downlink data packet from the first data network and belonging to the service connection; The processing unit is further configured to modify the destination IP address of the downlink data packet to the source IP address of the uplink data packet; and set the connection status of the connection tracking information to indication information indicating successful connection; The sending unit is further used to send the modified downlink data packet to the terminal.

9. A communication device, It is characterized in that The device comprises a processor and an interface circuit, wherein the processor is used to communicate with other devices through the interface circuit and execute the method according to any one of claims 1 to 4.

10. An IPv6 network system, It is characterized in that The method comprises a terminal, a first data network and the communication device according to any one of claims 5 to 9.

Citation Information

Patent Citations

  • Network filtering using router connection data

    EP3310015A1

  • Method for sending data packets in a data network during handover of a mobile node

    US20100303027A1